All guided builds

Guided buildstarter5 steps~14 min4 devices

ARP and MAC learning, side by side

Watch a host's ARP cache and a switch's MAC table fill from the very first frame — and see why a host never ARPs for anything beyond its gateway.

What you'll be able to do: Two hosts, a switch and a gateway, and the ability to read the two tables that make Ethernet work — which MAC answers for an IP, and which port leads to a MAC — including why a packet for a remote network carries the gateway's MAC.

Topics: ARP · MAC address table · Ethernet switching · Default gateway

What you'll build

Step by step

  1. 1. Place the switch and read its empty table

    Drag a switch onto the canvas and name it, then read its MAC address table. It is empty: a switch starts life knowing nothing about who is plugged in where, and it fills that table by itself, one arriving frame at a time.

    On SW-Access — Name the switch so its prompt says which box you are on

    enable
    configure terminal
    hostname SW-Access
    end

    Check: run show mac address-table on SW-Access and look for Total Mac Addresses for this criterion: 0.

    Why: The MAC address table maps each MAC address to the port it lives behind. A switch builds it from the SOURCE address of every frame it receives — nobody configures it, and nobody needs to.

  2. 2. Plug in two hosts — and let only one speak up

    Place two PCs and cable them to Fa0/1 and Fa0/2. Name both, but give an address to PC-Ana only, then read its ARP cache: empty, like the switch's table. A live cable and a typed address are not traffic, and neither table learns from anything else.

    • Cable PC-Ana Eth0 ↔ SW-Access Fa0/1
    • Cable PC-Ben Eth0 ↔ SW-Access Fa0/2

    On PC-Ana — Name the host, address it (with the gateway you will add later), and read its ARP cache

    hostname PC-Ana
    ipconfig Eth0 192.168.60.11 255.255.255.0 192.168.60.1
    arp -a

    On PC-Ben — Name the second host and leave it unaddressed for now

    hostname PC-Ben

    Check: run arp -a on PC-Ana and look for arp: no entries.

    Why: ARP (Address Resolution Protocol) is how a host turns the IP address it wants to reach into the MAC address it must write on the frame. The answers are cached — but only after a question has been asked, so a host that has sent nothing has nothing cached.

  3. 3. Address PC-Ben and send the first frame

    Give PC-Ben its address, then ping it from PC-Ana. The first thing on the wire is not the ping: PC-Ana broadcasts an ARP request — who has 192.168.60.12? — the switch floods it out of every other port and learns PC-Ana's MAC on Fa0/1 as it passes, and PC-Ben's reply teaches it Fa0/2. Read both tables now.

    On PC-Ben — Give the second host its address on the same subnet

    ipconfig Eth0 192.168.60.12 255.255.255.0 192.168.60.1

    On PC-Ana — Ping PC-Ben, then read the cache the ping filled

    ping 192.168.60.12
    arp -a

    Check: run show mac address-table on SW-Access and look for Total Mac Addresses for this criterion: 2.

    Why: Two tables did two different jobs: PC-Ana's ARP cache answered 'which MAC has this IP?' and the switch's table answered 'which port leads to this MAC?'. The request was flooded only because the switch could not yet know where anyone was — from now on, frames between these two hosts go down exactly one cable each.

  4. 4. Add the gateway and ping past it

    Place a router, cable its Gi0/0 to the switch's Gi0/1, and give Gi0/0 the gateway address 192.168.60.1 plus a loopback, 10.60.60.1/24, to stand in for a network beyond it. Ping 10.60.60.1 from PC-Ana and read its ARP cache: the new entry is 192.168.60.1 — the router. There is no entry for 10.60.60.1 at all.

    • Cable Edge Gi0/0 ↔ SW-Access Gi0/1

    On Edge — Name the router, make Gi0/0 the LAN's gateway, and put a network behind it

    enable
    configure terminal
    hostname Edge
    interface Gi0/0
    ip address 192.168.60.1 255.255.255.0
    no shutdown
    exit
    interface Loopback0
    ip address 10.60.60.1 255.255.255.0
    exit
    end

    On PC-Ana — Ping an address on another subnet, then read the cache again

    ping 10.60.60.1
    arp -a

    Check: run arp -a on PC-Ana and look for (192.168.60.1) at.

    Why: A host only ARPs for addresses on its own subnet. 10.60.60.1 is not, so PC-Ana hands the packet to its default gateway: it ARPs for 192.168.60.1 and writes the router's MAC on the frame, while the IP header still says 10.60.60.1. MAC addresses carry a frame across one link; IP addresses carry the packet all the way.

  5. 5. Clear both tables and watch them rebuild

    Both tables are caches, not configuration, so you can wipe them without changing a single setting. Clear the switch's MAC table, delete PC-Ana's ARP cache, then ping PC-Ben again: the ARP question is asked afresh, and the switch relearns exactly the two hosts that spoke — not the router, which has sent nothing since.

    On SW-Access — Empty the MAC address table

    enable
    clear mac address-table

    On PC-Ana — Empty the ARP cache, then talk to PC-Ben again

    arp -d *
    ping 192.168.60.12
    arp -a

    Check: run show mac address-table on SW-Access and look for Total Mac Addresses for this criterion: 2.

    Why: On a real network both tables forget idle entries by themselves — a switch after 300 seconds by default — so a host that moves or leaves is not remembered forever. Clearing them by hand is a standard troubleshooting move: it forces every entry to be relearned from live traffic, so what you read afterwards is the truth right now.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
ARP and MAC learning, side by side — step-by-step network lab · NetForge-AI